JOB SUMMARY:
The Manager Information Security Risk Management reports to the Vice President and Chief Information Security Officer (CISO) and develops, maintains and executes a continuous, flexible information security risk management program that aligns with Harris Health's overall strategic business and IT goals, and addresses the higher-risk areas and concerns of Executive Management. Works alongside the Harris County attorney team and the Harris Health corporate compliance department to review third-party contracts and ensure compliance to standards and regulations regarding information access, security, and privacy. Leads all phases of internal and third-party risk assessments as-well-as planned IT audits and reviews. Coordinates internal and third-party security audits, to include HIPAA audits, PCI DSS audits, Service Organization Controls (SOC) audits, ISO audits, SSAE 16 / ISAE 3402 audits, customer audits, and other compliance/regulatory audits. Assists VP/ CISO with decisions regarding risk and audit planning, testing plans and methodologies for risk and audit projects. Assists VP/CISO in determining reportable observations, findings and recommendations to relay to Executive Management and Board of Trustees. Develops and publishes cyber related risk and audit reports and reviews. Drafts and updates various departmental and organization-wide information security policies.
MINIMUM QUALIFICATIONS:
Education/Specialized training/Licensure:
Bachelors degree, Masters preferred
CISSP required. CRISC, CISA, HCISPP, CIPP, GSNA, or CCSP, must have obtained (1) additional certification within six (6) months of accepting position.
CISSP (required); Must have obtained one (1) additional certification within six (6) months of accepting position.
WORK EXPERIENCE:
6 years' work experience. Extensive knowledge of HIPAA Security rule, HITECH, Payment Card Industry (PCI), NIST Cybersecurity Framework. In addition, understanding of NIST SP 800-53r4, COBIT, and ITIL frameworks preferred. RSAM or other GRC tools experience preferred. Previous IT audit and risk management experience, or equivalent combination of education and experience.
MANAGEMENT EXPERIENCE:
Three (3) years of experience in Cyber Security or related field.
SPECIAL REQUIREMENTS:
Communication Skills:
Exceptional Verbal (Public Speaking
Writing/Composing: (Correspondence/Reports)
Other Skills:
Analytical, Statistical